ZeroHour

CVE-2017-1000107

CVSS 3.0
8.8 high
EPSS
1%p66
Published
()
Modified
Description

Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.

Vendors
jenkins
Products
script security
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.